The website of a group of Russian hackers aiming for infrastructure disappears a mystery



Ransomware attacks that take control of computers with malware and demand ransom are increasing in US infrastructure companies. President Biden made a proposal to Putin for a cyberattack at a meeting on June 16, 2021, as it was believed that the attack was carried out by a group of Russian hackers. And on July 13, it was reported that the website of the Russian hacker group in question had disappeared.

REvil, Hacking Group Behind Major Ransomware Attack, Disappears --The New York Times
https://www.nytimes.com/2021/07/13/us/politics/russia-hacking-ransomware-revil.html

REvil ransomware gang inexplicably vanishes from the internet --CNN
https://edition.cnn.com/2021/07/13/tech/revil-ransomware-disappears/index.html

In the United States, ransomware attacks targeting companies responsible for infrastructure, food, medical care, etc. are occurring frequently, and on May 31, 2021, meat trader JBS was attacked by ransomware. As a result, all beef factories were shut down, raising concerns about a global shortage of meat.

The world's largest meat company, JBS, was attacked by ransomware, and all beef factories in the United States were shut down.



The JBS factory was restored by June 3, but JBS has announced that it has paid the attackers a ransom worth $ 11 million.

It turns out that the ransom of 1.2 billion yen was paid to the ransomware attacker by JBS, the world's largest meat processor --GIGAZINE



This ransomware attack is believed to have been caused by the Russian cybercriminal organization REvil. In the United States priority of response to the ransomware attack is equivalent to terrorism has been raised to, at the meeting in Geneva was held on June 16, Biden the President should not be as the target of cyber attacks on President Putin ' It is reported to have indicated 'a prohibited area for cyber attacks'.

After the meeting, Putin said, 'The two countries need to abandon all kinds of speculation and discuss at the expert level and start working for the benefit of both the United States and Russia,' and began discussions on cybersecurity issues. He revealed that the two leaders had agreed to do so, but did not mention Mr. Biden's proposal.

However, on July 13, overseas news media CNN and others reported that 'REvil has disappeared from the Internet.' REvil had a website called 'Happy Blog' on the dark web , but several security researchers tried to access REvil's web page, including a ransom payment page, but they couldn't.

Although the cause of the disappearance of the website is not clear, there is a possibility that it 'disappeared because it attracted too much attention in the latest attack' and that it 'simply became inaccessible due to a technical problem'. I can think of it. 'It's too fast to conclude because the Happy Blog went down before and then came back,' said Brett Callow of cybersecurity firm Emsisoft.

in Security, Posted by darkhorse_log